CVE-2021-25468: Input Validation
Published Oct 6, 2021
·Updated
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.
Affected Software
3 affected components
Google Android=10.0
Google Android=11.0
Samsung Exynos
Event History
Oct 6, 2021
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25468.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1.'
3
What is the severity of CVE-2021-25468?
The severity of CVE-2021-25468 is medium, with a CVSS score of 4.4.
4
How does CVE-2021-25468 affect Android devices?
CVE-2021-25468 affects Android devices running version 10.0 and 11.0.
5
How can attackers exploit CVE-2021-25468?
Attackers can exploit CVE-2021-25468 to read arbitrary memory addresses.